Anonymity, tested

Is Tor Safe From Police?

Short answer: the network holds up better than almost anything else you'll use online. Long answer: almost nobody gets caught because someone broke Tor.

Tor's core design has never been broken by police. Almost every Tor-related arrest traces back to a mistake outside the network — a reused username, a slip in browser settings, an informant, old-fashioned undercover work — not a cracked encryption scheme.

In 2013, an FBI agent sat in a public library in San Francisco, two seats down from a laptop, and waited.

The laptop belonged to the man running the largest drug marketplace on the internet — a site built specifically so this moment couldn't happen. So what went wrong?

Layered abstract illustration of encrypted network relays
Network compromisesNo confirmed case of Tor's routing being 'cracked'
Usual cause of arrestsOperational security errors, not network attacks
Traffic visible to police?Only that you're using Tor, not what you're doing

TL;DR

Quick answer

Tor's network design has never been publicly confirmed as broken by police. Almost every arrest traces back to opsec mistakes, informants, or exploits aimed at websites — not the Tor network itself.

Last reviewed2026-07-25
Reading time7 min
DifficultyBeginner
EvidenceStrong
Founded byUS Naval Research Laboratory, mid-1990s
Core defenseThree-hop relay encryption ('onion routing')
What it hidesYour IP address and browsing destination from any single observer
What it doesn't hideAnything you type into the sites you visit
Biggest real-world riskHuman error, not mathematics

The setup

What Tor actually promises — and what it never did

Tor doesn't promise invisibility. It promises that no single point on the path between you and a website can see both who you are and what you're doing at the same time. Your traffic gets wrapped in three layers of encryption and bounced through three volunteer-run relays before it reaches its destination, and each relay only ever knows the hop before it and the hop after it. That's the whole trick.

Police departments know this. So does the NSA, which has said as much in its own leaked training documents over the years. The frustration bleeds through: Tor is annoying to attack directly. Which is exactly why almost nobody bothers trying.

The claim, broken into parts

  • Can police see who is using Tor? Generally yes — Tor use itself is visible to an ISP or network operator.
  • Can police see what a Tor user is doing inside the network? Not through the network itself.
  • Can police still catch a Tor user? Yes, routinely — almost always through means outside Tor.

The library arrest, in brief

  1. 2013

    FBI investigators track a Silk Road forum account back to an early Gmail signup made under a real name.

    The lead had nothing to do with breaking Tor's encryption.

  2. October 2013

    Agents confirm their suspect is logged into the site's admin panel in a San Francisco library.

    They needed him caught with the laptop open and unlocked.

  3. Arrest

    An agent grabs the open laptop before it can be closed or the screen locked.

    The case rested on physical timing, not digital forensics against Tor.

The network that stumps agencies isn't the problem

Court documents in most major dark-web takedowns read less like a codebreaking thriller and more like a comedy of small, human slip-ups.

Search the public record for a case where investigators cracked Tor's routing and you'll come up empty. Search for a case where someone got sloppy — reused a nickname, left a return address on a package, bragged in a chat log — and you'll be reading for a week.

It reframes the whole question. 'Is Tor safe' quietly becomes 'is the person using it careful,' which is a much less flattering question for most people to ask themselves.

Three things people get backwards

Myth

If police catch a Tor user, they must have broken the encryption.

Reality

Almost every documented case involves a mistake outside Tor — malware, a reused handle, an informant, a shipping address, or plain old surveillance of the physical world.

Myth

Using Tor makes you invisible to your internet provider.

Reality

Your ISP can typically see that you're connecting to the Tor network, even if it can't see where your traffic goes afterward. In some places, that alone draws attention.

Myth

Tor was built by criminals, for criminals.

Reality

It was developed with U.S. Naval Research Laboratory funding to protect government communications, and it's used today by journalists, activists, and ordinary privacy-conscious people far more than by anyone breaking the law.

If not the network, then what?

If Tor's routing genuinely holds up, how does law enforcement build cases against people using it at all?

Mostly by working the edges instead of the middle. Investigators plant undercover accounts inside marketplaces, follow the money once cryptocurrency gets cashed out through regulated exchanges, exploit bugs in the websites people visit rather than in Tor itself, and lean on old-fashioned informants. The network is the hard part to attack, so nobody serious tries.

Weighing the claim

How strong is the evidence on each side of 'Tor is safe from police'?

Strong supportSupports the main answer

No publicly confirmed case exists of Tor's onion routing itself being decrypted by an agency.

Drawn from security research.
Strong supportComplicates the main answer

The FBI has used browser exploits (malware delivered through compromised sites) to unmask specific Tor users in targeted operations.

Drawn from law-enforcement records.
Useful supportComplicates the main answer

Academic researchers have demonstrated theoretical traffic-correlation attacks against Tor under lab conditions with resources most agencies don't deploy in practice.

Drawn from security research.
Strong supportSupports the main answer

The overwhelming majority of dark-web prosecutions cite non-technical evidence — informants, financial trails, opsec mistakes — as the breakthrough.

Drawn from legal precedent.

The Navy built the thing outlaws now rely on

Tor exists in its current form partly because anonymity only works if lots of ordinary, boring people are using the same network as anyone with something to hide — a spy's traffic has to blend in with a student's.

That's not a side effect. It's the design principle. A network used only by criminals would make every user a suspect by default.

The safest thing about Tor might be its bad reputation

Tor gets treated in headlines as a criminal's tool, which quietly discourages the very crowd of ordinary users — researchers, journalists, people in restrictive countries — who make anonymity possible for everyone else in the first place. The scarier the reputation, the thinner the crowd to hide in.

Silk Road, again — but the second one

After the first Silk Road was seized in 2013, a successor site sprang up within a month. Its operator was caught not through a Tor exploit but because he used a personal email account to register the server hosting the site.

The pattern repeats across nearly every major dark-web takedown: the network held, the operator didn't.

Where the real risk sits

Software gets outdated

Outdated Tor Browser versions have occasionally carried bugs that were exploited to reveal users' real IP addresses.

Habits leak identity

Reusing a username, writing style, or even posting schedule across a pseudonymous account and a real one is how most people are actually identified.

The network is only one link

Whatever site you visit through Tor can still log what you type, and that data can be seized or subpoenaed independently of Tor.

depends

So — is it safe?

Tor's routing has a strong track record against direct attack. But 'safe from police' was never really the right test — 'safe from your own habits' is.

Treat Tor as a well-built lock on a door you still have to remember to shut. The lock isn't the weak point. People forget to shut the door.

Why this question keeps coming up

Every generation gets a new technology that promises to make people invisible, and every generation eventually discovers that invisibility was never really on offer — just a harder trail to follow. Tor didn't change human nature. People still talk too much, reuse passwords, and trust the wrong stranger. The interesting story was never really about the software.

The short version

  • No confirmed case shows Tor's core routing being broken by police.
  • Nearly all Tor-related arrests trace to mistakes made outside the network.
  • An ISP can usually see that you're using Tor, just not what you're doing inside it.
  • Outdated software and reused usernames are far bigger risks than the encryption itself.

Questions people ask

Where to go next

Is Tor the same thing as the dark web?

They get used interchangeably, and they really shouldn't be.

What was Silk Road?

The case that shaped how the public thinks about Tor for a decade.

Does the dark web exist anymore?

The marketplaces keep getting seized. They also keep coming back.

Can the dark web be hacked?

Turns out the attackers aren't always wearing badges.

Tor vs a VPN — what's the actual difference?

People assume they do the same job. They really don't.

The lock was never the problem

Tor did what it was built to do. The people it failed to protect mostly failed themselves first.

You now know

  • Tor's routing has no confirmed history of being broken by police.
  • Most arrests trace to mistakes made outside the Tor network.
  • ISPs can typically detect Tor use, but not the content or destination of that traffic.

Safety note

Educational, not operational

This article is informational and does not provide guidance for evading law enforcement.

Common myth

Myth vs reality

Myth

If police catch a Tor user, they must have broken the encryption.

Reality

Almost every documented case involves a mistake outside Tor — malware, a reused handle, an informant, a shipping address, or plain old surveillance of the physical world.

FAQs

Questions people ask

Sources

Further reading

  • United States v. Ross Ulbricht case filingsU.S. Department of Justice
  • Tor Project: How Tor WorksTor Project

Continue learning

Next useful step

Keep going

The next door is usually the interesting one

The answer you came for touches a few neighboring questions. These are the ones most likely to make the picture click.

What you should remember

The lock was never the problem

  • Tor did what it was built to do. The people it failed to protect mostly failed themselves first.
  • Tor's routing has no confirmed history of being broken by police.
  • Most arrests trace to mistakes made outside the Tor network.
  • ISPs can typically detect Tor use, but not the content or destination of that traffic.

A few useful next steps

Where this question wanders next

The dark web is less a single tunnel than a set of side passages. These are the useful ones from here.

If this made you wonder

tor collection

Check the evidence

1

Common Dark Web Myths, Debunked

Most of what people 'know' about the dark web arrived secondhand, from headlines about its worst corners. Here's a closer look.

2

What Are the Uses of Hidden Services on the Tor Network?

The New York Times runs one. So does a whistleblower drop box used by dozens of newsrooms. And, yes, so do some marketplaces you've heard of. Here's the full range.

3

What Is Tor Browser Used For?

Ask people what Tor Browser is for, and most will guess the dark web. Ask the Tor Project's own usage data, and you get a considerably longer, more ordinary list.

4

What Is The Dark Web?

Not a digital sewer. Not a myth. Just a small, locked room at the back of the internet you already use every day.

5

Has The FBI Ever Run A Dark Web Marketplace Undercover?

Not the FBI alone — but yes, in 2017, law enforcement secretly operated a major marketplace for nearly a month while its users had no idea.

Questions people ask first

Choose by the time in your pocket